Import table
advapi32.dll
CryptGenRandom, OpenProcessToken, DuplicateTokenEx, GetLengthSid, SetTokenInformation, CreateProcessAsUserA, ConvertStringSidToSidW, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, SetServiceStatus, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, GetTokenInformation, RegDeleteKeyW, RegQueryInfoKeyW, RegEnumKeyExW, RegSetValueExW, RegSetValueExA, RegOpenKeyA, CryptEncrypt, CryptAcquireContextW, CryptGenKey, CryptReleaseContext, CryptImportKey, CryptExportKey, CryptDestroyKey, RegOpenKeyExA, RegQueryValueExA, OpenSCManagerW, OpenServiceW, CloseServiceHandle, ConvertSidToStringSidA, AllocateAndInitializeSid, EqualSid, FreeSid, SetNamedSecurityInfoW, SetEntriesInAclW, GetEffectiveRightsFromAclW, GetNamedSecurityInfoW
kernel32.dll
GetProcessHeap, HeapFree, IsDebuggerPresent, UnhandledExceptionFilter, lstrcatW, lstrcpyW, lstrlenW, GetFullPathNameW, FindCloseChangeNotification, FindNextChangeNotification, FindFirstChangeNotificationW, FileTimeToLocalFileTime, OpenEventA, GetStartupInfoA, EnterCriticalSection, LeaveCriticalSection, GetLastError, InterlockedIncrement, InterlockedDecrement, Sleep, DeleteCriticalSection, InitializeCriticalSection, WaitForSingleObject, GetTickCount, CreateThread, CloseHandle, ProcessIdToSessionId, TerminateProcess, OpenProcess, GetModuleFileNameA, GetProcessTimes, GetExitCodeProcess, GetCurrentProcessId, GetModuleHandleW, GetCurrentThreadId, InterlockedCompareExchange, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetCurrentProcess, GetProcAddress, GetModuleHandleA, QueryPerformanceFrequency, SetLastError, GetFileAttributesW, InterlockedExchange, OutputDebugStringA, LoadLibraryA, GetCurrentThread, ResumeThread, GetThreadContext, SuspendThread, SleepEx, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, Module32NextW, Module32FirstW, FreeLibrary, CreateFileA, TlsGetValue, TlsAlloc, GetModuleFileNameW, VirtualQuery, RtlCaptureContext, GetSystemInfo, LocalFree, QueryDosDeviceA, MultiByteToWideChar, GetVersionExW, CreateFileW, WideCharToMultiByte, DeleteFileW, MoveFileW, CopyFileW, CreateDirectoryW, FindClose, RemoveDirectoryW, FindNextFileW, FindFirstFileW, FindNextFileA, FindFirstFileA, CompareFileTime, FlushInstructionCache, VirtualProtect, InterlockedExchangeAdd, GetSystemTime, SetEvent, WaitForMultipleObjects, ResetEvent, SetWaitableTimer, CancelWaitableTimer, CreateEventW, CreateWaitableTimerW, DeviceIoControl, ReadFile, GetSystemDirectoryA, GetWindowsDirectoryA, GetSystemTimeAsFileTime, lstrlenA, GetVolumeInformationA, FileTimeToSystemTime, CreateProcessW, GlobalFree, GlobalAlloc, LoadLibraryExA, GetFileAttributesA, IsWow64Process, GetFileTime
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoSetProxyBlanket, CoUninitialize, CoInitializeEx, CoCreateInstance, OleRun
psapi.dll
GetModuleInformation, GetModuleFileNameExA, EnumProcesses
rapportutil.dll
DllMain
shell32.dll
SHGetFolderPathW, SHGetFolderPathA
shlwapi.dll
PathAppendA, SHDeleteKeyW, AssocQueryStringA
trf.dll
iterate_pid_with_logs, env_alloc_default, stacktrace_get_stack_trace, counters_release, counters_acquire, env_is_inited, iterate_pid, env_get, get_application_directory, counters_get, GetCurrentSessionId, stacktrace_get_caller_module, stacktrace_get_stack_trace_unl, proctools_get_process_image_name, iterate_modules, set_application_directory
user32.dll
wsprintfW, MessageBoxA
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wininet.dll
InternetSetOptionA, HttpQueryInfoW, InternetGetConnectedState, InternetOpenA, InternetCrackUrlA, InternetCloseHandle, InternetReadFileExA, InternetSetStatusCallbackA, InternetSetOptionW, InternetConnectA, HttpOpenRequestA, HttpQueryInfoA, HttpSendRequestA
wtsapi32.dll
WTSFreeMemory, WTSQuerySessionInformationW, WTSEnumerateSessionsW, WTSQueryUserToken